LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-23-2011, 12:26 PM   #1
zmahomedy
LQ Newbie
 
Registered: Jul 2007
Posts: 2

Rep: Reputation: 0
International blockage on on ports


Hi I have a centos system on a static ip in South Africa
As of 5 days ago I lost connectivity on HTTP, SSH, and SIP to any international address expect within South Africa.
I did contact the service provider and they told me that there are not blocking any ports and everything seems fine on their side. My server is been colocated on their network.

Here are our diagnostics

1) I can ping from the box to any address using IP and DNS
2) I can ping from an international address to the box using IP and DNS.
3) I CAN NOT access HTTP, SSH, SIP from any clients outside SA.
3b) CAN access all ports within SA.

4)NMAP
[root@localhost ~]# nmap -T5 -sV localhost

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2011-05-23 18:52 SAST
Interesting ports on localhost.localdomain (127.0.0.1):
Not shown: 1671 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 4.3 (protocol 2.0)
80/tcp open http Apache httpd 2.2.3 ((CentOS))
443/tcp open ssl/http Apache httpd 2.2.3 ((CentOS))
787/tcp open status 1 (rpc #100024)

Service Info: OS: Unix

5) route -n
My server IP address is XXX.XXX.XXX.138

Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
XXX.XXX.XXX.136 0.0.0.0 255.255.255.248 U 0 0 0 eth0
0.0.0.0 XXX.XXX.XXX.137 0.0.0.0 UG 0 0 0 eth0


6) IPTABLE --list (when it stoped and used for testing)

iptables --list
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination


7) IPTABLES --list ( when its running )
Chain INPUT (policy ACCEPT)
target prot opt source destination
fail2ban-ASTERISK all -- anywhere anywhere
fail2ban-SSH tcp -- anywhere anywhere tcp dpt:ssh
DROP all -- 173.242.116.18 anywhere

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Chain fail2ban-ASTERISK (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere

Chain fail2ban-SSH (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere



any help will be greatly appreciated
thanks

Zak
 
Old 05-24-2011, 03:12 AM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,292

Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
I would do as follows.
1. Presume an international firewall.
2. Make a cool decision are you going to accept it, or go for breaking it (with associated risks).

If the former, end this thread; if the latter, for obvious reasons, end this thread.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
open ports for utorrent using iptables n close smpt to that ports shtorrent00 Linux - Networking 2 09-30-2008 03:34 PM
how? redirect apache2 outbound ports to specific ports w/iptables? nowshining Linux - Security 5 05-27-2008 02:46 AM
Advanced ip range blockage with iptables chibi Linux - Security 2 04-11-2006 01:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration